
Security Analyst - Vulnerability Management
- United Kingdom
- Permanent
- Full-time
Identify, assess, and classify vulnerabilities across the organization’s network, systems, applications, and databases using automated vulnerability scanning tools (e.g., Tenable, CrowdStrike, Armis, etc.).Vulnerability Analysis & Prioritization:
Analyze discovered vulnerabilities and provide risk-based assessments to determine severity and potential impact on business operations.
Collaborate with system owners and stakeholders to ensure appropriate prioritization based on criticality and business impact.Patch Management & Remediation:
Work with internal teams to coordinate patch management processes, ensuring that vulnerabilities are remediated in a timely and efficient manner.
Develop and track vulnerability remediation plans, providing regular status updates and ensuring completion.Risk Reporting & Documentation:
Prepare detailed reports and presentations for management, highlighting the status of vulnerabilities, trends, and risks.
Maintain up-to-date vulnerability management documentation, including vulnerability inventories, patch status, and remediation timelines.Security Tools & Technologies:
Leverage security tools and platforms to monitor and manage vulnerabilities, staying updated on emerging threats and vulnerabilities in the cybersecurity landscape.Collaboration & Training:
Work closely with IT, development, and operations teams to integrate vulnerability management practices into the software development lifecycle (SDLC) and system administration processes.
Provide guidance and training to staff on best practices for vulnerability identification, patching, and mitigation.Compliance & Standards Adherence:
Ensure that vulnerability management practices align with industry best practices, regulatory requirements (e.g., PCI-DSS, HIPAA, GDPR), and internal security policies.
Assist with internal audits and compliance assessments as required.WHAT THIS PERSON WILL BRINGExperience in cybersecurity, with a focus on vulnerability management and risk assessment.Understanding of common vulnerabilities and exposures (CVEs) and related risk assessment methodologies.Familiarity of security frameworks and standards (e.g., NIST, CIS, ISO 27001).Experience using vulnerability scanning tools (e.g., Tenable, Nessus, CrowdStrike, Armis).Familiarity with patch management processes and remediation strategies.Strong analytical, problem-solving, and troubleshooting skills.Excellent written and verbal communication skills, with the ability to effectively communicate technical concepts to non-technical stakeholders.Highly responsive, process-oriented, and proactiveStrong analytical and interpersonal characteristicsAbility to work both independently and collaborativelyEthical character with ability to keep information confidentialPassionate about cyber security, a desire to protect and help people; positive attitude and enjoys constantly learningWilling to respond to emergency situations off-hoursEqual OpportunitiesWe are passionate and committed to our people and go beyond the rhetoric of diversity and inclusion. You will be working in an inclusive environment and be encouraged to bring your whole self to work. We will do all that we can to help you successfully balance your work and homelife. As a growing business we will encourage you to develop your professional and personal aspirations, enjoy new experiences, and learn from the talented people you will be working with. It’s talent that matters to us and we encourage applications from people irrespective of their gender identity, race, sexual orientation, religion, age, disability status or caring responsibilities.